Campaigns
Archipelago Hide Office Documents and Cover Up Sneak Campaign With Recon Shark

Archipelago Hide Office Documents and Cover Up Sneak Campaign With Recon Shark

APT43KimsukyRecon SharkArchipelagoBlack BansheeThallium
The North Korean state sponsored threat actor known as Kimsuky has been discovered using a new reconnaissance tool called ReconShark as part of an ongoing global campaign

Indicators of Compromise

navernnail.com
foward.viewpropile.p-e.kr
wvw3.secure-edit.n-e.kr
yulsohnyonsei.atwewbpages.com
naver.o-r.kr
mc.pzs.kr
w3.secure-edit.n-e.kr
www1.quickedit.o-r.kr
k-bank.o-r.kr
kbank.o-r.kr
heungkukfire.p-e.kr
objshell.run
g1790.rt14v.com
goooglesecurity.com
dashboard.quikveoriy.o-r.kr
3.supports.o-r.kr
naver65.n-e.kr
gonamod.com
tos.p-e.kr
dmengineer.co.kr
worldinfocontact.club
wwv3.supports.o-r.kr
kamco.kbloan.r-e.kr
siekis.com
av2wg.rt14v.com
www2.configment.p-e.kr
conf.simpleedit.n-e.kr
ggc-partners.info
dcykcjqywclwqrwnweny.com
fegr23ylwp03yfvm.xyz
topyotanesla.top
nkxmtmkdfmeprilmhnud.com
cashsentinel.lives.com-change.info
moreofit.cn
accounts.google-signin.ga
menucraft2004b.com
hotrnail.com-change.info
davilafunds.com
59uabr.eanimininter.cloud
navers.com-change.info
zamorapitchg.com
intactoil2001b.com
lvv23blili03ujrxcp.xyz
cashsentinel.microsoft.com-change.info
msslrsa-motherson.com
myaccount.google.newkda.com
r2iomj.bdomunting.cloud
airmail.cc
haleassetss.com
lewisliftg.com
aucmoney.com
brokenislegion.tk
34trully.xyz
login.gmail-account.gq
lecuy.org
scancargo2010b.com
account.googgle.kro.kr
microsoft.adobeflash.cc
cashsentinel.navor.com-change.info
kniier.danomininter.cloud
rtaa21.badomininter.cloud
update.adobeflash.cc
sguumi.bdomunting.cloud
ciaociao.top
delemano.online
fivcgrcgrttorxbrfmrc.com
asfuuvhv3083f.xyz
moreeu.cn
cashsentinel.naver.com-change.info
69uabr.canomininter.cloud
axz1.xyz
dbcpnfjjoopaxfytlgwe.com
kuapakualaman.com
toldopened.press
thegymmum.com
berrytvs.com
marbellacabs.com
asfasfvcxvdbs.com
32iieb.badomininter.cloud
accounts.grnail-signing.work
wiskotoniks.buzz
76iiyb.cdonununting.cloud
novaksavingss.com
eclipso.ch
www.mobiessence.com
brokenethicalgod.ml
live.com-change.info
a8eefj.adonuting.cloud
postformt.com
getallopeerk3.host
muou49.eanimininter.cloud
publiccloud.navor.com-change.info
cashsentinel.com-change.info
wilkinstransportss.com
allianceline.bar
keithestates.com
mamujeeproduct.com
elevatorbernald.com
www.epcdiagnostic.com
loslhxtjjfqefcgwqeop.com
a1terainfra.com
hotmail.com-change.info
9847germany.bid
venuscera.top
24savetonnofmaoney.xyz
pottermanagements.com
aath22rzmo03mvewdj.xyz
vcsa0114.lowicz.work
a8aegj.edonuting.cloud
myaccounts.grnail-signin.ga
ddlovke.kr
bmwfor.com
skjflkjsjflejlkjieiieieiei.lives.com-change.info
texasfresnos.top
waet.adonuting.cloud
beg23crlsak03wwzwc.xyz
pospvisis.com
losmapes.com
despairdelivery2015b.com
jpyldhkgyarutaukmkyg.com
myaccount.grnail-security.work
lokiik.xyz
auxhtpwfrfbbjbwvbqat.com
parkerarrangeg.com
fazetaherotic.top
myaccount.grnail-signin.ga
b8eiq4.adomininter.cloud
commer-soft.com
stionsomi.ru
enrichuae.com
wigginsstorages.com
kalcimeroni.top
astrallis.fit
naver.loginsaa.gmail.com-change.info
naver.com-change.info
microsoft.loginsaa.grnail.com-change.info
bernardrentalss.com
samedime.pw
outlock.com-change.info
intaticducalso.ru
utilityderef.today
chmowd.xyz
paypal.com-change.info
myaccount.google.nkaac.net
6huabr.badomininter.cloud
kimyfrenotsure.uno
yonsei.lol
signin.grnail-login.ml
brewermeshg.com
bkxf24hfvt03ftrd.xyz
fasederro.site
50kindabag.xyz
emcrlctrihiqkkmbgcjy.com
ns2.microsoft-office.us
msupdt.net
savacons.com
3soakc.edonuting.cloud
vhsonlinesecurity.info
nanahanafi.top
eudimalinka.top
teamfinfintop.club
banweb.cityu.dev
gopstoporchestra.top
ywiigm.cdonununting.cloud
duvinodigatomia.bid
edfaeqghkkybanidbcxj.com
baaqtupcighnnpxwesyv.com
soitaab.co
waet.danomininter.cloud
eraa21.adomininter.cloud
51oon7.bdomunting.cloud
csmonkiliduat.top
military.co.kr
www.rnofinancial.com.au
madesecuritybusiness.com
codilmeosoterti.tk
4tresduo.uno
allthemilliplastini.space
darrassaad.com
gmail.com-change.info
frembonga.ga
merssed.com
hbawr.canomininter.cloud
cashsentinel.outlock.com-change.info
blog.prevailion.com
shanroban.com
gccorps.com
myaccount.cgmail.pe.hu
asterhalogabry.website
96iikr.bdomunting.cloud
www.dailysecu.com
atvcampingtrips.com
elexitodelonatural.com
medranooveng.com
texts.letterpaper.press
912caporers.fun
manager-alert.com
logrns.lives.com-change.info
hamiltonrecipeg.com
zau.divendesign.in
ds349onmo.online
nlds.navor.com-change.info
apponline354.ir
gyjmc.com
bmiiw6.danomininter.cloud
eemea3.ng.msg.eemea-microsoft.com
bipanenetess.top
fmiaee.adomininter.cloud
afha23ufwhkf03ajxy.xyz
gasonz.com
daskurilla.pw
payufe.com
microsoft.loginsaa.gmail.com-change.info
thereconnerd.com
volumeoil2015b.com
xniier.ddonuting.cloud
everyonemustbe.pw
klhlh16zldwun03vlpq.com
rtaa21.ddonuting.cloud
hessroughg.com
cashsentinel.hotmail.com-change.info
amrp.tw
alps.travelmountain.ml
carolinascarpelini.com.br
ddlove.kr
alliances.bar
photonewsiq.com
hk.studiteroom.email
priekornat.com
myaccount.google-signin.ga
aboasu.xyz
nyoo37.edonuting.cloud
com-change.info
ktaaot.adonuting.cloud
renatazarazua.com
mainchksrh.com
bennettsavingss.com
hxeier.adomininter.cloud
haleyqueenffff.xyz
benjithecat.com
www.hybridanalysis.com
ksewyaygxradkhvnriyn.com
smallgop.com
stornihivesturaf.club
kniier.adonuting.cloud
menoiras.space
dmitolt.com
navor.com-change.info
forsehauseg.top
brokenethicalgod.tk
suspam.com
wscript.shell.run
alliancer.bar
newblessings.cf
nocelmozzvi.top
tdalpacafarm.com
r.wlthplum.com
forkftriosilly.space
mtk23gqakwj03bzds.xyz
sukilomenfi.top
testdomain0x00.xyz
filipinekaus.top
yagoeallanaadegaltda.sellsyourhome.org
grnail.com-change.info
1fouvy.ddonuting.cloud
bergenpremieredentistry.us
tajbev.ga
montrealist.top
waet.cdonununting.cloud
gloporiente.ru
amadiohaowo.com
modewater.top
mercycarrolld.com
askenya.org
abnfjgsqwcdxxbuegewu.com
jimwdthorkbwkxamchff.com
myaccounts-gmail.kr-infos.com
feaser2347.club
microsoft.com-change.info
doc-view.work
fondfbr.com
blog.f4l1k.tk
ampfiadwrjeutqcuawqr.com
protect.grnail-signin.ga
lightopridum2.website
jzolonnen.xyz
ispaniolla.club
onedrive-upload.ikpoo.cf
macrodown.com
a3eedk.canomininter.cloud
outlook.com-change.info
75iitv.cdonununting.cloud
glancehcs.com
wara.danomininter.cloud
areteir.com
lamarfish.com
inifastkolin.club
nasufmutlu.com
timesilgeren.top
download.riseknite.life
curtainbeild.com
dicksonmuseumg.com
elmaaref.com
kennyamanek.top
edc-studio.com
ciaociaoline.com
newshare.online
etaa65.edonuting.cloud
landmark.net
limblarsond.com
naivenielsend.com
login.gmeil.kro.kr
accounts.lives.com-change.info
logws.lives.com-change.info
org-help.com
pandimesia.top
logmes.lives.com-change.info
feralhendown.xyz
loginsaa.gmail.com-change.info
accounts.grnail-signin.ga
downmail.navor.com-change.info
pistols.fit
hitnaiguat.xyz
cashsentinel.live.com-change.info
carpetoil2005b.com
72ioey.badomininter.cloud
hnwfoccrqxmcljriiclw.com
wlthplum.com
nmesecakahobymeghbkg.com
lives.com-change.info
loges.lives.com-change.info
camachovioling.com
loginsaa.grnail.com-change.info
derma360.ro
0soub8.eanimininter.cloud
semkil.xyz
user.mai1-help.com
altlass.com
electrabeautytools.com
myaccount.grnail-signing.work
cashsentinel.outlook.com-change.info
adobeflash.cc
accounts.live.com-change.info
myrbifhlqurcelkflmyf.com
natihoresilimi.top
myaccounts-gmail.autho.co
shawgardenings.com
hnnmuglfwbxqgubwsxdp.com
update.jean911nie.com
kqjtgacoawnsrorhxgoi.com
sadammanopore.cyou
w5iomk.eanimininter.cloud
ns1.microsoft-office.us
plutosalacia.top
96iitv.ddonuting.cloud
fegr23sylwp03yfvm.xyz
download.google-images.ml
knightmortgage2r.com
andersonbtcs.com
cashsentinel.navers.com-change.info
account.grnail-signin.ga
jonashartley.com
coloradospringsroofing.info
eneos.com.tw
entirelysecuritybusiness.com
filshilkamira.club
disagreemossd.com
accounts.goggle.hol.es
aaaaawwqwdqkidoemsk.lives.com-change.info
beanoil2007b.com
ma1l-help.com
cloud.navor.com-change.info
jgu16cbxdr03ehqvx.com
cashsentinel.hotrnail.com-change.info
a8eefk.canomininter.cloud
arviskeist.ru
accounts.google-manager.ga
sprayvillad.com
adjustoil2020b.com
jumpwashingtond.com
haleyqueenfff.xyz
stoolstorage2007b.com
stenion.bond
millscruelg.com
fqtk24zhwwj03soioea.xyz
mitmail.tech
signin.gmrail.ml
arkt.xyz
ip.rst.im
vupipess.com
pfnnupmhwwkhyyqroewi.com
idfn.top
kfps.top
10022020yes1t3481-service1002012510022020.ru
chpp.top
10022020rustest213-service1002012510022020.ru
snuff.mybabyrose.com
roofingspecialists.info
adagio.betterworldshopping.com
pelebra.atwebpages.com
www.hydrotec.co.kr
nfiuerwtftasnuk.com
triplonet.com.br
salofu.com
ahss.top
www.agrisic.info
civil-group.ir
equiposautomotriz.com
usctrqxmfptoslvqwcde.com
www.fessuseyyesseee.com
yzq24meogxq03bsvfu.xyz
random-fund-2007.com
siidocumentos.icu
lakf.top
birkett.com.au
10022020test134831-service1002012510022020.space
hservice.live
inferno.bigpurposebigimpact.com
phpmyadmin.xsunx.com
denverbbq.net
landmarklive.in
www.christopherngai.com
10022020test261-service1002012510022020.space
10022020newfolder1002002531-service1002.space
wclocukmwqwtdkbtdnfe.com
bmlor.750.credit
rsjb23tnxjng03dgiy.xyz
accountskakao.bim-mgn.com
lweonepal.com
edwinharrington54.xyz
olfs23kvri03wyyb.xyz
prompt.powerofpartnerships.net
mynameisgarfield.top
tayladanismanlik.com
nabudar.top
geniesoutien.com
inspirer.cartsandmowers.com
wagnerdonate.com
sklep.omax.pl
www.kncomputers.com
joke.webproduct.info
myaccounts.posadadesantiago.com
impresosypapeleriaocana.com
array.prototype.slice.call
10022020test41-service100201pro2510022020.ru
rpgceomskdrehfmapjrw.com
afhckrfcucjbpln.com
familystory.es
myhelpcare.cc
dominichampton59.xyz
time.suehyatt.com
fekiop3.space
mp.weixin.qq.com
informatify.net
nhelpcare.cc
desertkingresort.com
askcon.net
10022020newfolder1002002431-service1002.space
fhsl.top
venosur.top
deskcareme.live
joomla.lifepath.site
obunryugtpfyssw.ru
www.firstbirthdayphotoshoot.com
www.tgofilms.com
ovesf23knfg03eixqds.xyz
rehwctfffvvkvcukxaic.com
www.eventosatitlan.com
popcorn.net-zerodesign.com
freespace.givingprofits.net
zakriasons.co
hmcks.realma.r-e.kr
ns7.softline.top
test.news.pocketstay.com
mcdnn.net
debate-reilly2001.com
10022020est213531-service100201242510022020.ru
elivebox.net
xjnwqdospderqtk.ru
drazbargura.xyz
translate.google.com
10022020newfolder4561-service1002012510022020.ru
mpevalr.ria.monster
nyqualitypizza.top
libo-cc.com
reputinodaedo.pw
rusianlover.icu
petiteballerina.fi
10022020test136831-service1002012510022020.space
qgam.top
very-lam2018.com
fanta.swofficefurniture.com
www.evrocom.co.za
aras.iuc.ac
247secure.us
gallery.wineadam.com
yksletjuuwcdxxbmyvfu.com
sansec.io
tobocoq.com
plkiu.daniyalmedicaltech.com
nirvanaeyehospital.com
prce24izsje03aioy.xyz
againstpolicebrutality.top
vasprogramer.com
www.epsilon-me.com
www.rizrvd.com
admirer.onehourcfo.com
xxql.top
vuss.top
mm.portomnail.com
gyuw.top
zqykg24numnvu03cqebye.xyz
egusnkbawrrmqvj.ru
pointers.ecostratas.com
vtxa.top
ddim.co.kr
gscare.live
harold.jetos.com
osrsport.com
informaciones.siidocumentos.cu
10022020yirtest231-service1002012510022020.ru
becharnise.ir
fymm.top
standart.sdtranspo.com
eventosatitlan.com
torbrowser.io
bmpfkgsottkswfh.com
win03.xyz
hitfromthebong.top
gsghhd4fgaaaqhu.xyz
transcorpoil.com
tor-project.ru
10022020yest31-service100201rus2510022020.ru
www.dubainights.net
telete.in
upload.mydrives.ml
webtvparacatu.com.br
lnnrpwtstcbmdhn.com
10022020test51-service1002012510022020.xyz
zombie.susan-hyatt.com
mcdnn.me
jibw.top
tarifacabins.com
jooshineng.com
turktech.co.uk
www.squadzone.net
carpenter365.xyz
whitegarden.top
40ort.750.credit
eve.uedmei.com
group3.pulsedesigngroup.us
gogowormdealer.top
miyfandecompany.com
roaf.top
10022020test15671-service1002012510022020.tech
artist.capitaldstudio.com
wsbc23imtnnc03lrmpxa.xyz
alltestwork.com
tricilidiany.com
s91-update.mala7at.com
aeus.top
www.lillinx.com
elkytoursandtravel.com
ywxlxcrycqcgnpberbvv.com
www.fountainhead410.com
kraulerrrblast.xyz
scott254.xyz
10022020test146831-service1002012510022020.space
daddy.stlouisdemoday.com
rwstytlptsnrnmuocmha.com
flowers.netplusplans.com
kumarpropack.com
10022020newfolder33417-01242510022020.space
10022020newfolder1002002131-service1002.space
ns8.softline.top
validation.wootraining.certificacion.cl
10022020test12671-service1002012510022020.online
flowers.thegardnerco.com
10022020uest71-service100201dom2510022020.ru
crpa.top
builder.visionarybusiness.net
www.joomlas123.info
10022020test14781-service1002012510022020.info
wenkgefmpgfumtk.com
gdtech.kr
win01.xyz
iiql.top
slasinfo.com
playtime74.com
back.rooter.tk
tor-browser.io
combat.strategyforgood.com
slaweskicpa.com
yrorala.xyz
alvaelectrical.ir
thehealthandwellbeingclub.com
blog.garantitorna.com
pixelapn.adsprofitnetwork.com
stevens347.xyz
ggoz.top
ferguson356.xyz
dmkpheoqsfuvwxo.ru
schroederindustries.cf
10022020test13561-service1002012510022020.su
pixelapn2.adsprofitnetwork.com
defender5.coachwithak.com
www.tor-browser.ru
wifoweijijfoiwjweoi.xyz
samsung-drivers.xyz
wnsx22gdouo03tuyu.xyz
yapv.top
10022020utest1341-service1002012510022020.ru
techlog.xyz
signup-now.com
osdiyfgjyhpxketjmvgr.com
wwwid.bim-mgn.com
10022020test281-service1002012510022020.ru
olenfex.com
360tecnologico.com
werkplaats1.okker.nl
eletronicaeduardo.com.br
muqgllmqtyllhwn.com
mishpachton.club
www.appupravinexports.com
airseaalliance.com
10022020test11-service1002012510022020.press
10022020newfolder1002002231-service1002.space
autopartslarry.top
help.mappo-on.life
csji.top
servrhost.xyz
anirban24tv.com
coal.top
www.856380692.xyz
www.hikayemedya.com
anderson4375.xyz
10022020rest21-service1002012510022020.eu
bestroyelgroup.com
ynwrrqhijdskprryphwf.com
www.basiclablife.com
www.glamotd.com
porcarabanchel.es
method.nonprofitsustainability.com
hiolop4.fun
nhelpcare.info
seafirst-kr.com
gillespieindex.com
puwthcdbvvyoxutgfpkj.com
10022020yomtest251-service1002012510022020.ru
mansizeprofile.top
10022020test125831-service1002012510022020.space
mail.beetleorchid.in
viio.top
nid.bim-mgn.com
robotvice.com
rock.core-thought.com
pureaqua.pk
csv.posadadesantiago.com
www.torrbrowser.ru
ruxuluymrdgwyvjetbbs.com
nationalngofederation.com
vafc.top
leer-afrikaans.co.za
www.tor-browser-free.ru
oracledispatch.com
perfeck42.uno
printing.laminatesandthings.com
e-anjab.jatimprov.go.id
pqdb.top
www.gym-gain.bid
sethisabelle.website
q.promossupply.com
qmnhylypxwaniufhylqk.com
lion.vipjoyeria.com
10022020test61-service1002012510022020.website
sztianhao.en.china.cn
simplithy.co.uk
dikan.co.za
champions.gdtc.org
gellyoema.xyz
ns9.softline.top
new.bombill.com
promo9.promossupply.com
context.septemberyears.org
usy15wycqme03dymh.xyz
myhelpcare.online
aogedvhwqhuokpd.ru
10022020test147831-service1002012510022020.space
help.octo-manage.net
dfdfjkbcv.net
tanzaniafisheries.com
edgethefoundation.com
aslambek.eu
www.prodaft.com
10022020test13461-service1002012510022020.net
erikareese347.xyz
hefuaqbanking.com
helper.canvas-life.me
mbhpikampombehi.com
klickprints.com
rdraj16rwjw03xnli.com
sasremetgausal.tk
10022020newfolder3100231-service1002.space
optimalwellengineering.com
fasfjfjjigrinnsj.xyz
salon26north.com
qvqy23thdsed03xjeqtf.xyz
tria.ge
mboard.baydevelopments.com
jettyplus.com
backup.awarfaregaming.com
bpqx.top
miriammoreno124.xyz
hannatrain.com
annejoseph643.xyz
www.bekagayrimenkul.com
eurasiacl--kr.com
rtfv.info
2fmp.weixin.qq.com
octoberx2.online
idiolos.work
login.daum.kcrct.ml
usernaver.com
account.daum.unikortv.com
login.microsoftonline.org-view.work
sankei.sslport.work
www.group.email.tlsmain.work
intranet.ohchr.org-view.work
naver.pw
account-viewer.work
dorey.work
help.unikoreas.kr
naohisashibuya.sslport.work
smtper.org
mail.rfanews.sslport.work
login.daum.net-accounts.info
webmain.work
view-hanmail.net
desk-top.work
member-authorize.com
gloole.net
daum.unikortv.com
check-onedrive.org-vps.work
login.yahoo.account-protect.work
onedrive.sslport.work
nidlogin.naver.corper.be
ww-naver.com
naver.unibok.kr
spmode.smt.docomo.account-protect.work
myetherwallet.com.mx
sts.desk-top.work
com-vps.work
amaniafrica-et.org-view.work
naverdns.co
logins.daum.net-sec.pw
pro-navor.com
exiweng.work
spmode.smt.docomo.ne.jp-ssl.work
www.active.onedrive.tlsmain.work
nid.naver.onektx.com
vilene.desk-top.work
com-sslnet.work
login.account-protect.work
cloudnaver.com
nid.naver.unicrefia.com
nid.naver.unibok.kr
com-auth.work
daum.net.pl
org-vip.work
account.live.account-protect.work
resultview.com
naver.koreagov.com
naver.cx
login.outlook.kcrct.ml
org-vps.work
naver.com.pl
sslserver.work
jp-ssl.work
mailsnaver.com
system.save
nytimes.onekma.com
login.daum.unikortv.com
login.gordonchang.org-view.work
unrepong.work
naver.com.se
servicenidnaver.com
groups.email.account-protect.work
downloadman06.com
www.registry.ohchr.tlsmain.work
www.intranet.ohchr.tlsmain.work
www.anca-aste.it
read-hanmail.net
active.onedrive.tlsmain.work
impression.poulsen.work
mail.org-vip.work
shacc.kr
naver.co.in
webmail.org-view.work
amberalexander.ghtdev.com
naver.com.ec
click.onedrive.account-protect.work
member.daum.uniex.kr
account.daum.unikftc.kr
demand.poulsen.work
intranet.ohchr.account-protect.work
login.yahoo.com-service.org-view.work
www.astedams.it
kinac.work
doc-view.account-protect.work
read-naver.com
drive.cloud.com-download.work
com-active.work
hogy.desk-top.work
yahoo-info.work
com-download.work
org-view.work
msolui80.inc
doc-view.docomo.ne.org-view.work
login.yahoo.co.jp.org-view.work
beyondparallel.sslport.work
mail.doc-view.pw
help-navers.com
desk.poulsen.work
nidnaver.net
securetymail.com
top.naver.onekda.com
intemet.work
poulsen.work
owa.com-download.work
com-ssl.work
1drv.ms.account-protect.work
com-option.work
verdall.xyz
robezo.work
myaccount.account-protect.work
cloudmail.cloud
riaver.site
csnaver.com
registry.ohchr.tlsmain.work
login.aei.org-view.work
naver.com.cm
jonga.ml
login.un.org-view.work
ns.onekorea.me
kooo.gq
login.bignaver.com
delegate.un.account-protect.work
login.yahoo.co.jp-sec.pw
preview.manage.org-view.work
dutaley.work
nid.naver.com.se
member.daum.unikortv.com
intranet.ohchr.org-view.pw
org-view.pw
offerhubs.org-view.work
com-accountprotect.work
loadmanager07.com
nid.naver.corper.be
quickconnect.io
helpnaver.com
coinone.co.in
net.tm.ro
daurn.org
spurgentaction.in.ohchr.org-view.work
default.tokyo
myetherwallet.co.in
naver.onegov.com
tiosuaking.com
myaccounts.gmail.kr-infos.com
intranet.ohchr.tlsmain.work
1drv.ms.doc-view.pw
read.tongilmoney.com
account-protect.work
login-yahoo.org-view.work
wave.posadadesantiago.com
msdatl3.inc
nidnaver.email
smtper.cz
check-onedrive.robezo.work
ssltop.work
comment.poulsen.work
dubai-1.com
ohchr.org-view.work
marryyouinme.sslport.work
rtyuio.work
statement.poulsen.work
account.live.poulsen.work
webuserinfo.com
taplist.work
eastsea.or.kr
cooper.center
vpstop.work
view-naver.com
www.ne-ba.org
naver.com.mx
myaccount.nkaac.net
mail.unifsc.com
resetprofile.com

APT Groups1

Kimsuky

<b>Description of MISP:</b> This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.<br><br><b>Description of Mitre:</b> Kimsuky is a North Korean-based threat group that has been active since at least September 2013. The group focuses on targeting Korean think tank as well as DPRK/nuclear-related targets. The group was attributed as the actor behind the Korea Hydro & Nuclear Power Co. compromise.[1][2]<br><br><b>Description of Etda:</b> (Kaspersky) For several months, we have been monitoring an ongoing cyber-espionage campaign against South Korean think-tanks. There are multiple reasons why this campaign is extraordinary in its execution and logistics. It all started one day when we encountered a somewhat unsophisticated spy program that communicated with its “master” via a public e-mail server. This approach is rather inherent to many amateur virus-writers and these malware attacks are mostly ignored.<br><br>

Black BansheeVelvet ChollimaKimsukyITG16APT 43TA427TA406ARCHIPELAGOEmerald SleetThalliumSharpTongueKTA082

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Remediations
  • Exploring the specific techniques used by ReconShark, the persistence mechanisms, and how it evades detection will be helpful for organizations looking to defend against such threats.Mitigation Strategies: it is important to implement defensive measures, but it would be helpful to provide specific mitigation strategies that organizations can use to protect themselves from Kimsuky's tactics. This may include employee training on identifying phishing emails, implementing strong email filtering systems, using endpoint protection solutions, and performing regular security checks.
  • Indicators of Danger (IOCs): Sharing IOCs such as known malicious email subjects, sender addresses, filenames, and URLs used by Kimsuky will be valuable for organizations to proactively identify and block potential attacks.Incident Response and Reporting: Provide guidance on how organizations should respond in the event of a Kimsuky attack, including the steps to isolate and contain compromised systems, gather evidence, and report incidents to the relevant authorities or cybersecurity organizations. It will help you prepare.
  • Case Studies or Real-Life Examples: Including case studies or real-life examples of organizations targeted by Kimsuky can provide concrete examples of the threat and its impact. This can help readers understand the potential consequences of a Kimsuky attack and motivate them to take appropriate preventive measures.

Observed Countries250

AD (497)
AE (733)
AF (231)
AG (435)
AI (206)
AL (910)
AM (541)
AO (110)
AQ (402)
AR (151)
AS (225)
AT (500)
AU (666)
AW (388)
AX (274)
AZ (683)
BA (497)
BB (302)
BD (295)
BE (630)
BF (442)
BG (995)
BH (233)
BI (587)
BJ (260)
BL (863)
BM (15)
BN (556)
BO (267)
BQ (953)
BR (947)
BS (302)
BT (404)
BV (547)
BW (885)
BY (435)
BZ (827)
CA (885)
CC (408)
CD (210)
CF (378)
CG (831)
CH (695)
CI (754)
CK (492)
CL (318)
CM (969)
CN (157)
CO (872)
CR (215)
CU (183)
CV (81)
CW (475)
CX (459)
CY (824)
CZ (898)
DE (33)
DJ (18)
DK (382)
DM (905)
DO (79)
DZ (436)
EC (924)
EE (955)
EG (19)
EH (929)
ER (917)
ES (609)
ET (713)
FI (145)
FJ (586)
FK (870)
FM (169)
FO (190)
FR (672)
GA (236)
GB (32)
GD (345)
GE (536)
GF (997)
GG (969)
GH (665)
GI (71)
GL (261)
GM (778)
GN (94)
GP (221)
GQ (823)
GR (439)
GS (804)
GT (863)
GU (533)
GW (853)
GY (697)
HK (665)
HM (933)
HN (89)
HR (255)
HT (845)
HU (945)
ID (725)
IE (955)
IL (888)
IM (60)
IN (466)
IO (643)
IQ (299)
IR (737)
IS (211)
IT (365)
JE (800)
JM (721)
JO (537)
JP (910)
KE (764)
KG (642)
KH (765)
KI (632)
KM (391)
KN (249)
KP (403)
KR (727)
KW (912)
KY (200)
KZ (962)
LA (267)
LB (729)
LC (602)
LI (678)
LK (592)
LR (596)
LS (217)
LT (363)
LU (849)
LV (550)
LY (780)
MA (92)
MC (796)
MD (328)
ME (252)
MF (488)
MG (439)
MH (476)
MK (895)
ML (40)
MM (860)
MN (389)
MO (123)
MP (731)
MQ (801)
MR (276)
MS (843)
MT (712)
MU (9)
MV (92)
MW (458)
MX (148)
MY (257)
MZ (604)
NA (618)
NC (902)
NE (90)
NF (606)
NG (89)
NI (573)
NL (262)
NO (861)
NP (966)
NR (688)
NU (54)
NZ (505)
OM (762)
PA (773)
PE (129)
PF (739)
PG (115)
PH (985)
PK (413)
PL (120)
PM (515)
PN (801)
PR (739)
PS (565)
PT (637)
PW (61)
PY (133)
QA (466)
RE (23)
RO (548)
RS (506)
RU (2)
RW (824)
SA (699)
SB (783)
SC (30)
SD (94)
SE (178)
SG (188)
SH (547)
SI (935)
SJ (857)
SK (540)
SL (592)
SM (53)
SN (297)
SO (99)
SR (90)
SS (444)
ST (732)
SV (974)
SX (926)
SY (175)
SZ (146)
TC (4)
TD (937)
TF (826)
TG (866)
TH (955)
TJ (254)
TK (679)
TL (269)
TM (941)
TN (719)
TO (256)
TR (445)
TT (825)
TV (111)
TW (863)
TZ (858)
UA (980)
UG (531)
UM (208)
US (680)
UY (934)
UZ (661)
VA (957)
VC (665)
VE (64)
VG (415)
VI (153)
VN (697)
VU (144)
WF (52)
WS (522)
XK (655)
YE (80)
YT (77)
ZA (850)
ZM (310)
ZW (773)